Pass Your Cisco 350-201 Exam with Correct 141 Questions and Answers
Latest [Feb 20, 2022] 2022 Realistic Verified 350-201 Dumps
NEW QUESTION 59
An API developer is improving an application code to prevent DDoS attacks. The solution needs to accommodate instances of a large number of API requests coming for legitimate purposes from trustworthy services. Which solution should be implemented?
- A. Restrict the number of requests based on a calculation of daily averages. If the limit is exceeded, temporarily block access from the IP address and return a 402 HTTP error code.
- B. Increase a limit of replies in a given interval for each API. If the limit is exceeded, block access from the API key permanently and return a 450 HTTP error code.
- C. Apply a limit to the number of requests in a given time interval for each API. If the rate is exceeded, block access from the API key temporarily and return a 429 HTTP error code.
- D. Implement REST API Security Essentials solution to automatically mitigate limit exhaustion. If the limit is exceeded, temporarily block access from the service and return a 409 HTTP error code.
Answer: C
NEW QUESTION 60
Drag and drop the actions below the image onto the boxes in the image for the actions that should be taken during this playbook step. Not all options are used.
Answer:
Explanation:
NEW QUESTION 61
An organization is using a PKI management server and a SOAR platform to manage the certificate lifecycle.
The SOAR platform queries a certificate management tool to check all endpoints for SSL certificates that have either expired or are nearing expiration. Engineers are struggling to manage problematic certificates outside of PKI management since deploying certificates and tracking them requires searching server owners manually.
Which action will improve workflow automation?
- A. Integrate a PKI solution within SOAR to create certificates within the SOAR engines to track, update, and monitor problematic certificates.
- B. Implement a new workflow within SOAR to create tickets in the incident response system, assign problematic certificate update requests to server owners, and register change requests.
- C. Integrate a SOAR solution with Active Directory to pull server owner details from the AD and send an automated email for problematic certificates requesting updates.
- D. Implement a new workflow for SOAR to fetch a report of assets that are outside of the PKI zone, sort assets by certification management leads and automate alerts that updates are needed.
Answer: D
NEW QUESTION 62
The incident response team was notified of detected malware. The team identified the infected hosts, removed the malware, restored the functionality and data of infected systems, and planned a company meeting to improve the incident handling capability. Which step was missed according to the NIST incident handling guide?
- A. Contain the malware
- B. Install IPS software
- C. Perform vulnerability assessment
- D. Determine the escalation path
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 63
An engineer notices that unauthorized software was installed on the network and discovers that it was installed by a dormant user account. The engineer suspects an escalation of privilege attack and responds to the incident. Drag and drop the activities from the left into the order for the response on the right.
Answer:
Explanation:
NEW QUESTION 64
An engineer is analyzing a possible compromise that happened a week ago when the company database servers unexpectedly went down. The analysis reveals that attackers tampered with Microsoft SQL Server Resolution Protocol and launched a DDoS attack. The engineer must act quickly to ensure that all systems are protected. Which two tools should be used to detect and mitigate this type of future attack? (Choose two.)
- A. SHA512
- B. autopsy
- C. firewall
- D. IPS
- E. Wireshark
Answer: C,E
NEW QUESTION 65
Refer to the exhibit.
Where are the browser page rendering permissions displayed?
- A. x-test-debug
- B. x-content-type-options
- C. x-xss-protection
- D. x-frame-options
Answer: B
NEW QUESTION 66
Drag and drop the telemetry-related considerations from the left onto their cloud service models on the right.
Answer:
Explanation:
NEW QUESTION 67
A cloud engineer needs a solution to deploy applications on a cloud without being able to manage and control the server OS. Which type of cloud environment should be used?
- A. IaaS
- B. SaaS
- C. PaaS
- D. DaaS
Answer: A
NEW QUESTION 68
Refer to the exhibit.
What is the connection status of the ICMP event?
- A. blocked by a configured access policy rule
- B. allowed in the default action
- C. blocked by an intrusion policy rule
- D. allowed by a configured access policy rule
Answer: D
NEW QUESTION 69
Refer to the exhibit. What is the connection status of the ICMP event?
- A. blocked by a configured access policy rule
- B. allowed in the default action
- C. blocked by an intrusion policy rule
- D. allowed by a configured access policy rule
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 70
After a recent malware incident, the forensic investigator is gathering details to identify the breach and causes. The investigator has isolated the affected workstation. What is the next step that should be taken in this investigation?
- A. Review audit logs for privilege escalation events.
- B. Analyze the applications and services running on the affected workstation.
- C. Compare workstation configuration and asset configuration policy to identify gaps.
- D. Inspect registry entries for recently executed files.
Answer: D
NEW QUESTION 71
A Mac laptop user notices that several files have disappeared from their laptop documents folder. While looking for the files, the user notices that the browser history was recently cleared. The user raises a case, and an analyst reviews the network usage and discovers that it is abnormally high. Which step should be taken to continue the investigation?
- A. Run the w command
- B. Run the sudo sysdiagnose command
- C. Run the who command
- D. Run the sh command
Answer: B
NEW QUESTION 72
An engineer returned to work and realized that payments that were received over the weekend were sent to the wrong recipient. The engineer discovered that the SaaS tool that processes these payments was down over the weekend. Which step should the engineer take first?
- A. Organize a meeting to discuss the services that may be affected
- B. Request that the purchasing department creates and sends the payments manually
- C. Contact the incident response team to inform them of a potential breach
- D. Utilize the SaaS tool team to gather more information on the potential breach
Answer: D
NEW QUESTION 73
Drag and drop the cloud computing service descriptions from the left onto the cloud service categories on the right.
Answer:
Explanation:
NEW QUESTION 74
A threat actor has crafted and sent a spear-phishing email with what appears to be a trustworthy link to the site of a conference that an employee recently attended. The employee clicked the link and was redirected to a malicious site through which the employee downloaded a PDF attachment infected with ransomware. The employee opened the attachment, which exploited vulnerabilities on the desktop. The ransomware is now installed and is calling back to its command and control server. Which security solution is needed at this stage to mitigate the attack?
- A. endpoint security solution
- B. web security solution
- C. network security solution
- D. email security solution
Answer: C
NEW QUESTION 75
What is the impact of hardening machine images for deployment?
- A. reduces the steps needed to mitigate threats
- B. increases the availability of threat alerts
- C. increases the speed of patch deployment
- D. reduces the attack surface
Answer: D
NEW QUESTION 76 
Refer to the exhibit. Cisco Rapid Threat Containment using Cisco Secure Network Analytics (Stealthwatch) and ISE detects the threat of malware-infected 802.1x authenticated endpoints and places that endpoint into a Quarantine VLAN using Adaptive Network Control policy. Which telemetry feeds were correlated with SMC to identify the malware?
- A. NetFlow and SNMP
- B. NetFlow and event data
- C. event data and syslog data
- D. SNMP and syslog data
Answer: C
NEW QUESTION 77
A security architect in an automotive factory is working on the Cyber Security Management System and is implementing procedures and creating policies to prevent attacks. Which standard must the architect apply?
- A. IEC62446
- B. IEC62443
- C. IEC62439-3
- D. IEC62439-2
Answer: B
NEW QUESTION 78
A security manager received an email from an anomaly detection service, that one of their contractors has downloaded 50 documents from the company's confidential document management folder using a company- owned asset al039-ice-4ce687TL0500. A security manager reviewed the content of downloaded documents and noticed that the data affected is from different departments. What are the actions a security manager should take?
- A. Measure confidentiality level of downloaded documents.
- B. Report to the incident response team.
- C. Communicate with the contractor to identify the motives.
- D. Escalate to contractor's manager.
Answer: B
NEW QUESTION 79
......
Get 2022 Updated Free Cisco 350-201 Exam Questions and Answer: https://prepaway.dumptorrent.com/350-201-braindumps-torrent.html